How it works
- After authentication and policies admit the request, the gateway collects every message’s text content plus
promptandinput. - Each rule is matched across that text. A rule contributes its score once per request, however many times or segments it matches.
- The scores are summed. If the total reaches
firewall.threshold, the firewall trips. - The team’s mode decides what happens: nothing (
off), a recorded finding (audit), or a403(enforce).
Rules
| Rule | Score | Signals |
|---|---|---|
instruction_override | 60 | ”ignore/disregard/forget … previous/system … instructions”, “your new instructions are” |
prompt_exfiltration | 60 / 50 | ”reveal/print/repeat … system prompt / hidden instructions”, “what is your system prompt” |
role_confusion | 60 / 50 | Chat-template tokens (<|im_start|>, [INST], <<SYS>>), smuggled "role": "system" |
jailbreak_persona | 50 | ”DAN mode”, “do anything now”, “jailbreak”, “evil mode”, “no longer an AI” |
safety_bypass | 50 | ”without/bypass … restrictions/filters/guardrails”, “you are now unrestricted” |
invisible_chars | 50 | Zero-width characters, bidi overrides, Unicode tag characters and other invisible format characters |
system_line | 25 | A line starting system: |
developer_mode | 25 | ”developer mode”, “god mode” |
base64_payload | 25 | A base64 blob of 80+ characters that decodes |
Configuration
Key fields
Mode for every team that does not set its own. Any value other than
off, audit or enforce stops startup.The summed score at which a request trips. Lower is stricter.
Per-team override:
off, audit or enforce. Empty inherits default_mode.| Mode | On a trip |
|---|---|
off | The firewall does not run. |
audit | The request continues. Rule hits are stored on the request’s audit record and the metric is incremented. |
enforce | The request is refused with 403 before PII redaction, guardrails or any provider call. |
gateway.yaml by the gateway process. The per-team override is stored on the team and is set through the teams API below (or teams[].firewall_mode in gateway.yaml).
What a block returns
403, its findings (source firewall, the rule name and score), and a redacted copy of the body when bodies are recorded. No tokens are consumed.
Common configurations
Roll out safely: audit first
Roll out safely: audit first
Keep
default_mode: audit, watch manylayers_firewall_events_total and the audit findings for a week, then switch high-risk teams to enforce.POST /admin/teams creates the team or, if an organization team with that name exists, updates it. The update replaces monthly_token_budget, rpm_limit, tpm_limit, cache_enabled, firewall_mode and default_config_id with what you send, so include the team’s current values; models changes only when you send it. It requires org.teams.manage and refuses (409) a name used by a workspace team.Exempt an internal red-team
Exempt an internal red-team
Set
firewall_mode: off on that team only; everyone else keeps the default.Stricter scoring
Stricter scoring
Lower
threshold to 25 so every single signal, including a bare system: line or a long base64 blob, trips the firewall. Expect more false positives on technical prompts.Metrics
| Metric | Labels | Meaning |
|---|---|---|
manylayers_firewall_events_total | team, mode | Requests that tripped the firewall. mode is audit or enforce. |
Firewall vs. the prompt_injection guardrail
| Firewall | prompt_injection guardrail | |
|---|---|---|
| Scope | Whole deployment, per-team mode | Per workspace or organization, applied by rules |
| Scoring | Summed across the whole request | Per message segment |
| Tuning | One threshold | sensitivity (low 80, medium 50, high 30), threshold 1–100, categories |
| Modes | off, audit, enforce | enforce, enforce_but_ignore_on_error, audit |
| Block response | 403 prompt_injection | 403 guardrail_block |
The firewall inspects request text only. It does not scan model output or tool results returned in later turns unless they are sent back as message content.
Next steps
Guardrails
Configure the
prompt_injection guardrail per workspace.PII Detection & Redaction
The step that runs right after the firewall.
Metrics
Every Prometheus series the gateway exports.
Request Logging & Audit
Find blocked requests and their findings.